FundamentalsTLS22 Apr 2026 · 6 min read
The five HTTP headers that fix most of your browser-side problems
Most of the browser-side attacks against small business sites are stopped by five lines of server config. Here is what each one does, which ones I still see missing in 2026, and the one that most people turn on wrong.
Read →Email securityDNS10 Apr 2026 · 7 min read
SPF, DKIM, DMARC: the afternoon that stops people sending invoices as you
The FBI tracks billions of dollars a year lost to attackers who email your customers pretending to be you, and the ACCC logs tens of millions more from Australian businesses. The DNS records that bounce the forged mail take four hours to set up, cost nothing, and most businesses still don't have them.
Read →FundamentalsDNSTLS1 Apr 2026 · 6 min read
The twenty-minute audit I do on every new client website
The short, opinionated checklist I actually run on a small business website before I bill them for anything bigger. Not a best-practices listicle. The things I've found broken on sites with real revenue, in order.
Read →ASMFundamentals18 Mar 2026 · 5 min read
Attack surface management, without the vendor slideware
What ASM actually is when you strip the gartner quadrant off it, why I think small businesses need it more than the enterprise ones that buy it, and how to start without hiring anyone.
Read →